Php Nuke

Vendor:

First CVE: Nov 16, 2001 · Active for 24 years

31
Total CVEs
More Total CVEs than 96% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Php Nuke over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2001
24 years ago
Most Recent CVE
Apr 7, 2021
1,934 days ago

CVE Severity & Scoring

Php Nuke31 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (9.7%)
Unknown28 (90.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (9.7%)
High0 (0.0%)
Unknown28 (90.3%)
User Interaction
None2 (6.5%)
Unknown28 (90.3%)
Required1 (3.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (9.7%)
Unknown28 (90.3%)

Top CVEs

Signals from CVEs in this product scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.
Dec 31, 20048.838NOYES
Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file with (1) .htm, (2) .html, or (3
Oct 28, 20089.033NOYES
SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php
Feb 14, 20127.532NOYES
Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable.
Nov 16, 20017.532NOYES
There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state is not validated to
Apr 7, 20219.829NONO
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote attackers to execute arbitrary
Oct 25, 20067.529NOYES
SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] parameter to modules.php.
Jun 2, 20147.528NOYES
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the
Sep 14, 20097.528NOYES
SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.p
Aug 24, 20097.528NOYES
SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.
Jun 1, 20097.528NOYES

Exploit Exposure

Signals from CVEs in this product scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
48.4% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (31 CVEs).

Media Mentions

Signals from CVEs in this product scope (31 CVEs).

Top CNAs Publishing CVEs For Php Nuke

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.3.319.82.4%00
8.317.52.2%01
8.126.31.8%01
8.0.025.91.1%00
8.066.01.5%03
7.975.91.0%00
7.896.01.0%01
7.796.01.0%01
7.696.01.0%01
7.596.01.0%01
7.496.01.0%01
7.396.01.0%01
7.296.01.0%01
7.196.01.0%01
7.0106.21.1%01
6.946.51.0%00
6.846.51.0%00
6.746.51.0%00
6.646.51.0%00
6.566.61.0%00